VulnerabilityModified
CVE-2020-15051
Stored XSS exists via the Server Domain Name, Your Email Address, Group Name, MYSQL Server, Database, MYSQL Username, Group Name, and Task Description fields.
MEDIUM 6.1EPSS 2.47%
Does this matter?
Lower severity and a low EPSS score (2.47%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Artica Proxy before 4.30.000000. Stored XSS exists via the Server Domain Name, Your Email Address, Group Name, MYSQL Server, Database, MYSQL Username, Group Name, and Task Description fields.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 2.47% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- articatech/artica proxy
- Source
- cve@mitre.org
References
- http://artica-proxy.com/telechargements/Vendor Advisory
- https://github.com/pratikshad19/CVE-2020-15051Exploit, Third Party Advisory
- http://artica-proxy.com/telechargements/Vendor Advisory
- https://github.com/pratikshad19/CVE-2020-15051Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.